1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cdquasar: 1ba40977 — xClient.Core rebranded variant, v1.3.0.0, May 2026 build
Executive Summary — A near-stock build of a Quasar-derived open-source .NET RAT, compiled May 2026, with namespaces rebranded from Quasar.Client/Quasar.Common to xClient.Core. Unobfuscated .NET Framework 4.0 Client Profile PE32 (~348 KB). No packing, no obfuscation, no CAPE detonation possible. The OpenCTI 9d2ca3 label is a misattribution; this binary shares zero build artefacts with the MinGW/Go/.NET dropper cluster.
What It Is
- File:
1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd.bin, 348 KB (356,352 bytes) ^[file.txt] - Format: PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections ^[file.txt]
- Toolchain: .NET Framework 4.0 Client Profile / CLR v4.0.30319, linker v8.0, compiled Thu May 28 05:07:02 2026 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Assembly version: 1.3.0.0 ^[pefile.txt:233] ^[exiftool.json:27]
- Version info: InternalName
Client.exe, OriginalFilenameClient.exe, FileVersion1.3.0.0; all other fields (CompanyName, ProductName, LegalCopyright, FileDescription) are blank ^[exiftool.json:36-46] - Signed: No ^[rabin2-info.txt:27]
- Packed / obfuscated: None. Entropy of
.textsection 6.45 (typical for unobfuscated CIL). ^[pefile.txt:92] - Dynamic analysis: Skipped — no CAPE Windows guest available. ^[dynamic-analysis.md]
Family attribution is high-confidence: the binary contains the literal namespace strings xClient.Core.MouseKeyHook, xClient.Core.ReverseProxy.Packets, xClient.Core.Recovery.Browsers, xClient.Core.Registry, xClient.Core.Compression, xClient.Core.NetSerializer, xClient.Core.Packets.ServerPackets, and xClient.Core.Packets.ClientPackets throughout the string table. ^[strings.txt:57] ^[strings.txt:166] ^[strings.txt:210] ^[strings.txt:556] ^[strings.txt:711] ^[strings.txt:975] ^[strings.txt:1070] ^[strings.txt:1282] ^[strings.txt:1567] ^[strings.txt:1617] These namespaces map one-to-one onto the Quasar RAT architecture (see quasar); xClient.Core is the historical predecessor namespace from the xRAT codebase that Quasar was forked from. The NetSerializer library (custom serialization, not protobuf-net) was the original transport layer in early Quasar/xRAT builds. ^[strings.txt:1617]
The OpenCTI 9d2ca3 tag assigned at triage is a false positive. The 9d2ca3 cluster is characterised by MinGW-w64 encrypted droppers, Go infostealers, and lightweight .NET stagers — none of which match this .NET Framework 4.0 full-featured RAT. ^[entities/9d2ca3.md]
How It Works
Quasar is a modular .NET RAT with a plugin-like command architecture. The client binary connects to a Quasar/xRAT server; the C2 host/port are configured at build time or injected post-build. Communication uses the custom NetSerializer binary protocol over TCP sockets. ^[strings.txt:1617] ^[capa.txt]
Key modules visible in unobfuscated CIL metadata:
- Keylogging: Global hooks via
xClient.Core.MouseKeyHook. Capa detectslog keystrokes via polling(2 matches). ^[strings.txt:210] ^[capa.txt] - Credential harvesting:
xClient.Core.Recovery.Browsersnamespace + capagather chrome based browser login information. ^[strings.txt:975] ^[capa.txt] - Remote shell:
DoShellExecute/DoShellExecuteResponsemessage types. ^[strings.txt:1208] ^[strings.txt:1436] - File manager: Chunked file transfer via
FileSplit+FileChunk(implied byMaxBlocks,CurrentBlock,Blockpacket fields). ^[strings.txt:1159] - Desktop / webcam capture:
GetMonitors,MonitorIndex,DoWebcamStop,VideoCaptureDevice,AForge.Video.DirectShow. ^[strings.txt:1135] ^[strings.txt:2118] ^[strings.txt:2149] - Reverse proxy:
ReverseProxyConnect,ReverseProxyDisconnect,ReverseProxyData. ^[strings.txt:166] ^[strings.txt:196] ^[strings.txt:200] - System information:
GetSystemInfo,GetSystemInfoResponse, OS version query, network interface enumeration, drive listing, process enumeration, geo-location query. ^[strings.txt:1200] ^[strings.txt:1424] ^[capa.txt] - Registry manipulation: Full read/write/delete on HKCU/HKLM;
RegistryEditor,RegistrySeeker,RegSeekerMatch. ^[strings.txt:711] ^[strings.txt:737] ^[strings.txt:763] - Persistence:
DoStartupItemAdd,DoStartupItemRemove, and capaschedule task via schtasks(2 matches). ^[strings.txt:1150] ^[strings.txt:1207] ^[capa.txt] - Self-update / uninstall:
DoClientUpdate,DoClientUninstall. ^[strings.txt:1232] ^[strings.txt:1278] - Cryptography: Capa reports DPAPI encryption, SHA1/SHA256 hashing, Base64 encode/decode, and AES via
Rfc2898DeriveBytes+AesCryptoServiceProvider. ^[capa.txt] ^[strings.txt:1534] ^[strings.txt:1538] - Process injection / manipulation:
CreateProcess,TerminateProcess,SuspendThread,VirtualAllocequivalents via .NETProcess/ThreadAPIs. ^[capa.txt]
No hardcoded C2 host, port, mutex, or password is visible in plaintext strings — the builder injects these at compile time or stores them in an encrypted config block not recoverable statically. Without runtime detonation, C2 IOCs are absent.
Decompiled Behavior
Not applicable. The binary is pure .NET CIL (not native x86 code) and Ghidra does not produce meaningful pseudo-C from CIL. The assembly is completely unobfuscated — behaviour is recoverable directly from static strings, capa, and pefile metadata without decompiler output. No control-flow obfuscation, no string encryption, no anti-debug checks, and no anti-VM logic were identified.
C2 Infrastructure
Not recoverable statically. The Quasar/xRAT builder injects C2 credentials at compile time; they are not stored as plaintext resources in this sample. No IP addresses, domains, URL patterns, or mutex names were found in the string table. ^[strings.txt] Without dynamic execution or access to builder output / campaign artefacts, C2 IOCs are absent.
Interesting Tidbits
- Namespace rebrand evasion: The threat actor (or builder operator) changed
Quasar.Client→xClient.Coreand stripped theMaxXorcopyright, but left every other artefact intact —AForge,MouseKeyHook,NetSerializer, and the full packet type enumeration. This is a superficial rebrand, not a fork. ^[strings.txt] - Version down-grade: Assembly version
1.3.0.0is lower than the well-documented1.4.1.0builds in corpus siblings. This suggests either an older codebase or a deliberate version rollback to evade signature-based detection. ^[pefile.txt:233] - Blank version-info fields: Unlike stock Quasar builds that carry
Quasar Client/Copyright © MaxXor, this sample blanks all human-readable fields except InternalName/OriginalFilename (Client.exe). ^[exiftool.json] - No evasion at all: No anti-VM, no anti-debug, no sandbox detection, no sleep loops, no WMI/CPUID checks. A stock open-source build dropped straight onto a victim. ^[capa.txt]
- FLOSS failure: The flare-floss invocation failed with an argument-parsing error (
--noflag collision with the sample path). ^[floss.txt] Decoded strings were unnecessary — the assembly is unobfuscated. - Recent build date: Compiled May 28 2026 — this is a actively maintained/build variant, not a stale 2014-era artefact. ^[pefile.txt:34]
How To Mess With It (Homelab Replication)
Goal: Build your own Quasar/xRAT client and compare its capa fingerprint to this sample.
- Clone the public repository:
git clone https://github.com/quasar/Quasar.git(or the historical xRAT fork). - Open
Quasar.slnin Visual Studio 2019/2022. - In the
Clientproject, rename namespaces fromQuasar.Client/Quasar.CommontoxClient.Coreto match this rebrand. - Build the
Clientproject in Release mode targeting .NET Framework 4.0 Client Profile. - The output
Client.exewill carry the same capa namespace hits:compiled to the .NET platform,create TCP socket,send data,receive data,encode data using Base64,hash data using SHA1,log keystrokes via polling,query or enumerate registry key,create process in .NET, etc. - Verification: Run
capa Client.exe. The capability table should closely match this sample'scapa.txt— expect ~60+ host-interaction hits, ~10 communication hits, and the same ATT&CK tactic coverage. - Learning outcome: You will see exactly how a namespace-rebranded .NET RAT looks in strings and capa — useful baseline for spotting superficial evasion attempts.
Deployable Signatures
YARA rule
rule quasar_xclient_rebrand
{
meta:
description = "Quasar/xRAT variant rebranded with xClient.Core namespace — v1.3.x build fingerprint"
author = "Titus"
date = "2026-08-18"
sha256 = "1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd"
strings:
$ns1 = "xClient.Core.MouseKeyHook" ascii wide
$ns2 = "xClient.Core.ReverseProxy.Packets" ascii wide
$ns3 = "xClient.Core.Recovery.Browsers" ascii wide
$ns4 = "xClient.Core.Packets.ServerPackets" ascii wide
$ns5 = "xClient.Core.Packets.ClientPackets" ascii wide
$ns6 = "xClient.Core.NetSerializer" ascii wide
$ns7 = "xClient.Core.Registry" ascii wide
$ns8 = "xClient.Core.Compression" ascii wide
$msg1 = "DoShellExecute" ascii wide
$msg2 = "DoStartupItemAdd" ascii wide
$msg3 = "GetPasswords" ascii wide
$msg4 = "GetSystemInfo" ascii wide
$msg5 = "DoClientUpdate" ascii wide
$lib1 = "AForge.Video.DirectShow" ascii wide
$lib2 = "MouseKeyHook" ascii wide
$ver1 = "Client.exe" wide
condition:
uint16(0) == 0x5A4D and
filesize < 500KB and
4 of ($ns*) and
2 of ($msg*) and
1 of ($lib*) and
$ver1
}
Sigma rule
title: Quasar/xRAT xClient.Core Variant Execution
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: 'Client.exe'
- OriginalFileName: 'Client.exe'
selection_pe:
- Product: 'Client'
- InternalName: 'Client.exe'
selection_dll_load:
- ImageLoaded|contains:
- 'AForge.Video.DirectShow'
- 'MouseKeyHook'
selection_network:
Initiated: true
DestinationPort:
- 4782
- 4783
- 4784
- 4785
condition: 1 of selection_*
falsepositives:
- Legitimate Quasar/xRAT remote administration tool use (rare in enterprise; correlate with approved software inventory)
level: high
IOC list
| Type | Value | Notes |
|---|---|---|
| SHA256 | 1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd |
This sample |
| File name | Unknown (triage filename=file) |
Original distribution filename not recovered |
| Original filename | Client.exe |
Version-info field |
| Internal name | Client.exe |
Version-info field |
| Assembly version | 1.3.0.0 |
.NET metadata |
| Library | AForge.Video.DirectShow |
Webcam capture |
| Library | MouseKeyHook (namespace xClient.Core.MouseKeyHook) |
Global keyboard/mouse hooks |
| Library | xClient.Core.NetSerializer |
Custom binary TCP serialization |
| Registry keys | HKLM\Software\Microsoft\Windows\CurrentVersion\Run |
Startup persistence (generic) |
| Registry keys | HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
Startup persistence (generic) |
| Scheduled task | Created via schtasks |
capa detection; generic pattern |
Behavioral fingerprint
This binary is an unobfuscated .NET Framework 4.0 Client Profile PE32 executable with the internal name Client.exe and version 1.3.0.0. On execution it will load xClient.Core.MouseKeyHook for global keyboard capture, initialise the xClient.Core.NetSerializer TCP transport layer, and open outbound TCP connections to an operator-configured C2 server. It enumerates the local system (processes, drives, registry, network interfaces, geo-location), logs keystrokes, captures screenshots and webcam frames via AForge.Video.DirectShow, and supports remote shell execution, file-manager operations, reverse proxy tunneling, and browser credential recovery. Persistence is established via registry Run keys or scheduled tasks. No sandbox evasion, no anti-debug, and no packing is present — a superficially rebranded stock open-source RAT build.
Detection Signatures
capa → MITRE ATT&CK mapping (static-only, no runtime confirmation from CAPE):
| capa capability | ATT&CK Technique |
|---|---|
| gather chrome based browser login information | T1555.003 |
| log keystrokes via polling | T1056.001 |
| reference WMI statements / access WMI data | T1047 |
| schedule task via schtasks | T1053.005 |
| encode/decode data using Base64 | T1140 / T1027 |
| encrypt data using DPAPI | T1553.005 |
| create TCP socket / send data / receive data | — (generic communication) |
| query or enumerate registry key/value | T1012 |
| create process in .NET | T1129 |
| set registry value | T1112 |
| enumerate processes | T1057 |
| get OS version / get hostname / get MAC address | T1082 |
| get geographical location | T1614 |
| bypass Mark of the Web | T1553.005 |
References
- Open-source project: https://github.com/quasar/Quasar (MaxXor)
- Historical predecessor: xRAT / xClient codebase (namespaces preserved in this variant)
- Artifact ID:
30f3a412-a744-421e-8059-829970a3e2bf - Source: OpenCTI → MalwareBazaar (mislabelled
9d2ca3) - Family page: quasar
Provenance
- This report synthesized from static analysis outputs in
raw/analyses/1ba40977145dbff6f52243c28807e08847b5675f4e835bed557ed04ad37f40cd/:file.txt,pefile.txt,exiftool.json,rabin2-info.txt— build metadata and version infostrings.txt— unobfuscated .NET namespace and message-type enumeration (2,539 lines)capa.txt— capability detection and ATT&CK mapping (static scope)binwalk.txt— PNG icon in.rsrcat offset 0x17F81floss.txt— command-line invocation failure; no decoded strings neededdynamic-analysis.md— CAPE skipped (no Windows guest)
- radare2 analysis: opened with
mcp_radare2_open_file, CIL architecture confirmed, 3,072 functions analysed at level 2 - Tools: file v5.44, pefile 2023.2.7, ExifTool 12.76, radare2 5.9.2, capa v8.0.1, flare-floss (failed invocation), binwalk 2.3.2